CVE-2026-5301 is a stored cross-site scripting (XSS) vulnerability in CoolerControl's log viewer component affecting versions prior to 4.0.0. The flaw enables unauthenticated attackers to inject malicious JavaScript code into log entries, which is then executed when the logs are viewed. This vulnerability permits complete service compromise through stored XSS payloads that persist in log data. The attack has a CVSS score of 6.1 (Medium severity) with a network-based attack vector requiring no authentication or special privileges, though user interaction is necessary to trigger the payload. The vulnerability could result in limited confidentiality and integrity impacts with the ability to affect systems beyond the immediate application boundary. The EPSS score of 0.00028 indicates minimal observed exploitation prevalence in the wild. This vulnerability is not currently listed on the Known Exploited Vulnerabilities (KEV) catalog and is marked as inactive on industry hot lists, suggesting no active exploitation campaigns are documented at this time. While the FAUCET risk score of 43.0/100 suggests moderate concern, the low EPSS prevalence indicates limited real-world exploitation activity or publicly available exploit code. Organizations running CoolerControl versions below 4.0.0 should prioritize patching to address the unauthenticated XSS vector.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.0.0CPE matchmatch criteria | cpe:2.3:a:coolercontrol:coolercontrold:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.